CVE-2025-25015

Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors
Configurations

No configuration.

History

02 Apr 2025, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441', 'source': 'bressers@elastic.co'}
  • () https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441 -
Summary
  • (es) La contaminación de prototipos en Kibana conduce a la ejecución de código arbitrario a través de una carga de archivo manipulada y solicitudes HTTP manipuladas específicamente. En las versiones de Kibana &gt;= 8.15.0 y &lt; 8.17.1, esto es explotable por los usuarios con el rol de Visor. En las versiones de Kibana 8.17.1 y 8.17.2, esto solo es explotable por los usuarios que tienen roles que contienen todos los siguientes privilegios: flee-all, integrations-all, shares:execute-advanced-connectors

05 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-05 10:15

Updated : 2025-04-02 17:15


NVD link : CVE-2025-25015

Mitre link : CVE-2025-25015

CVE.ORG link : CVE-2025-25015


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')